The data protection officer is the GDPR’s built-in internal supervisor: an expert who advises, monitors, and serves as the regulator’s contact point, protected from instruction and dismissal so the advice stays honest. Articles 37 to 39 govern when the role is mandatory, how it must be positioned, and what it does.
| Regulation | GDPR, Articles 37 to 39 |
|---|---|
| Max penalty | EUR 10M or 2% of global turnover (Art. 83(4)) |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
When you need one
Article 37(1) sets three triggers: public authorities (always), core activities requiring regular and systematic large-scale monitoring (behavioral advertising networks, telecoms, location-tracking apps), and core activities involving large-scale special category or criminal data (hospitals, insurers, background-check providers). “Core activities” means processing integral to the business, not payroll or ordinary IT support.
Member state law can extend the duty. Germany’s BDSG requires a DPO whenever at least 20 people are regularly involved in automated processing of personal data, which captures most German companies of any size. Even where not required, many organizations appoint one voluntarily; note that a voluntary DPO carries the same legal obligations as a mandatory one.
Independence is the hard part
Article 38 is where appointments fail. The DPO must be involved in all data protection issues in a timely manner, resourced adequately, given no instructions regarding the exercise of the tasks, protected from dismissal or penalty for performing them, and must report to the highest level of management. Article 38(6) allows other tasks only where they create no conflict of interest.
The conflict rule has teeth. The Belgian DPA fined a company EUR 50,000 in 2020 because its DPO simultaneously headed compliance, audit, and risk, meaning he would audit his own decisions. The same logic disqualifies CIOs, heads of HR, and marketing directors. The safe pattern: appoint someone who advises on processing but never decides it.
Qualifications and structure
The GDPR requires expert knowledge of data protection law and practices proportionate to the processing (Article 37(5)), but no specific certification. A group of companies may appoint a single DPO if easily reachable from each establishment, and external DPO services satisfy the regulation fully. What matters in an audit: the appointment is documented, contact details are published and filed with the authority, the DPO’s advice appears in DPIA records, and there is evidence management actually consulted the DPO before major decisions.
For the assessments the DPO advises on, see our DPIA guide. And since Article 37(7) requires your DPO contact to appear publicly, a free scan checks whether your privacy notice includes it.